CVE 7.3 HIGH

Moodle: moodle: cross-site scripting vulnerability via inadequate input filtering in formula editor_CVE-2025-67850

7.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Description

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.

Basic Information

ID CVE-2025-67850
Source fedora
Published Feb 3, 2026 at 10:52

Affected Product

Version 5.1.0
Affected Versions 4.1.0
4.4.0
4.5.0
5.0.0
5.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.